The short answer
Under the EU NIS2 Directive, municipalities and city operators (utilities, transport, water, waste, public-administration digital services) that qualify as essential or important entities must treat the ICT supply chain as a managed risk, not a purchasing chore. Article 21 requires assessing each direct supplier's vulnerabilities, the quality of its products and secure-development practices, and factoring in EU-wide critical supply chain assessments. Because top management is accountable and supervisors may audit your records, every supplier decision should be documented and repeatable.
Key takeaways
- Not every municipality is in scope: whether you are an essential or important entity depends on the sector in Annexes I–II, the national size threshold, and how your Member State has listed public bodies and city operators.
- Article 21(2)(d) makes supply chain security a mandatory risk-management measure, and Article 21(3) requires considering each direct supplier's specific vulnerabilities, product quality and secure-development practices.
- The EU ICT Supply Chain Security Toolbox (adopted by the NIS Cooperation Group in early 2026) plus ENISA's technical implementation guidance give practical, evidence-oriented methods a municipality can adopt.
- Supplier vetting belongs across the whole procurement cycle: from tender questions and contract clauses to right-to-audit, incident-notification timing and a documented exit plan.
- Essential entities typically face proactive (ex ante) supervision and heavier fines, so written evidence on each critical supplier — an owner, a risk level, a review date — is non-negotiable.
- A certificate is not proof of practice: weigh incident history, subcontractors, secure-development processes and dependence on a single vendor or a third-country supplier.
Is your municipality or city operator in scope?
Before vetting suppliers, confirm whether the organisation falls under NIS2 (Directive (EU) 2022/2555). It replaced the 2016 NIS1 and widened coverage to 18 critical sectors, adding public administration at central and regional level and encompassing the sectors where city operators typically work: energy, water, transport, and waste and wastewater management. Being a municipality is not, by itself, the deciding test: sector plus classification under national law determines your duties.
The directive uses a general size-cap rule — as a rule medium and large entities (in the region of 50 employees and above) are covered, along with certain small and micro enterprises with a key societal or economic role. Member States were required to transpose the directive by 17 October 2024, but implementation has been uneven; the Commission has already referred several Member States to the Court of Justice for failing to notify transposition measures and, in January 2026, proposed amendments to simplify compliance.
The practical step is to check your national implementing law and the official lists maintained by the competent authority. A city-owned utility that is the sole supplier of a critical service to a region, or that operates a network, is often treated as an essential entity even with modest headcount. That classification drives the intensity of supervision and therefore how deep your supplier checks must be.
What Article 21 requires of supplier relationships
Article 21 obliges entities to take appropriate and proportionate technical, operational and organisational measures based on an all-hazards approach. Among its ten minimum measures, point (d) names supply chain security, including security-related aspects of relationships with direct suppliers and service providers. In effect, the supply chain is treated as a source of risk that your risk-analysis and information-security policies must address.
The decisive detail sits in Article 21(3): when choosing supply-chain measures, an entity must take into account the vulnerabilities specific to each direct supplier or service provider, the overall quality of products and cybersecurity practices — including secure-development procedures — and the results of coordinated security risk assessments of critical supply chains at Union level (Article 22(1)). In short, a generic yes/no questionnaire is not enough; assessment must be individualised and reflect how a given supplier actually builds, patches and maintains what it delivers.
For a municipality this means segmenting suppliers by criticality and access, then evaluating development and maintenance practices such as vulnerability handling and service continuity. NIS2 also makes members of management personally accountable for non-compliance, so supplier decisions must be documented, reasoned and traceable rather than informal.
New EU tools to anchor your checks
At EU level there are now practical reference points a municipality can use as a baseline. The NIS2 Cooperation Group — Member States, the European Commission and ENISA — adopted the EU ICT Supply Chain Security Toolbox, a common approach to identifying, assessing and mitigating cybersecurity risks across ICT supply chains. It outlines risk scenarios and recommends mitigation measures, including assessing critical suppliers, pursuing multi-vendor strategies and reducing dependence on high-risk suppliers, including exposure to third-country influence.
ENISA separately published its NIS2 Technical Implementation Guidance (June 2025) for entities in the digital infrastructure, ICT service management and digital provider sectors, whose obligations are detailed in Commission Implementing Regulation (EU) 2024/2690. The guidance offers practical advice, concrete examples of evidence and mappings of security requirements to international standards and national frameworks. Although it targets digital providers, its method — what counts as demonstrable implementation of supply-chain security measures — is a useful model for a municipal operator negotiating with cloud, managed-service or software suppliers.
These documents do not replace national law, but they narrow uncertainty and give public buyers a shared vocabulary. They show how states and public authorities can demand assessment of critical suppliers, vendor diversification and measures against high-risk suppliers. For a municipality they are simultaneously a checklist for reviewing its own digital providers and leverage in contract talks.
Embedding checks across the procurement cycle
Sound vetting begins before signature. In the tender you should ask open, answerable security questions rather than collect ticks: where data is stored and processed, how the supplier has handled incidents in recent years, its secure-development and patching process, which certifications it holds and who its subcontractors are that touch your systems. Document the answers in a supplier file that can later support your Article 21 assessment.
The contract should lock in: the supplier's duty to maintain agreed security measures; incident-notification timelines aligned with your own NIS2 reporting obligations; the right to audit and inspect; business-continuity and recovery commitments; and an exit plan covering data return and migration on termination. For public procurement this means expressing security as technical specifications and award or selection criteria in the tender documentation up front, not bolting it on later.
Vetting is a cycle, not a one-off. Reassess suppliers on a defined cadence: ownership or jurisdiction changes, new incidents, expired certifications and shifting reliance on subcontractors all warrant review. Keep a supplier map by risk tier with review dates. Where a supplier is itself a NIS2-scoped digital or critical entity, its own obligations reduce — but do not remove — your responsibility to check.
Governance, supervision and audit-ready evidence
Because NIS2 makes management personally accountable, supplier evidence is what a supervisor will request first. Essential entities are generally subject to proactive (ex ante) supervision, meaning the authority can request materials and run checks without waiting for an incident; important entities are mostly supervised reactively (ex post), after an incident or complaint. Even as an important entity, lacking supplier documentation is a liability the moment any review begins.
Run a supply-chain risk register: for each critical supplier record an owner, risk level, assessment findings, mitigation measures and a review date. Keep correspondence, questionnaires, certificates and audit reports as evidence. Link every measure back to Article 21(3) — explain how you accounted for the supplier's specific profile and secure-development practices rather than relying on a blanket policy.
Two caveats. First, this is EU law: thresholds, lists, penalties and notification deadlines sit in national implementing acts and can change, so verify the current position in your Member State. Second, this guidance is general information, not legal advice for your specific jurisdiction or contract.
Put it into practice
Supplier due-diligence checklist for an NIS2-scoped municipality or city operator
Run this checklist for every ICT or OT supplier supporting an in-scope service — before award and then on a set cycle (for example annually). Keep the outputs in the supplier risk register as evidence for the competent authority.
- Confirm which in-scope service the supplier supports and assign a named risk owner.
- Tier the supplier high/medium/low by access, service criticality, data sensitivity and jurisdiction exposure.
- Request a current security questionnaire or valid certificate (for example ISO/IEC 27001) and verify scope and expiry, not just existence.
- Review the supplier's incident history and disclosure behaviour over the past two to three years.
- Assess secure-development, vulnerability-management and patching practices for delivered products and services.
- Establish which subcontractors (fourth parties) can access your data or operate your services.
- Evaluate vendor lock-in and switchability: are alternatives available, and is a multi-vendor strategy feasible?
- Negotiate contract terms covering security measures, incident-notification timing, right to audit, continuity and exit/data return.
- Check whether the supplier is itself in NIS2 scope and align mutual obligations.
- Document the decision in the risk register with the Article 21(3) rationale, an owner and a review date.
Questions people ask
Which municipalities and city operators actually fall under NIS2?
Scope depends on sector and national classification, not on the label 'municipality'. NIS2 covers public administration at central and regional level and the critical sectors where city operators work (energy, water, transport, waste and wastewater). As a rule, medium and large entities (about 50 employees and above) and certain key small enterprises are covered. Member States define the lists and split between essential and important entities, so check your national implementing law and the competent authority's register rather than the EU text alone.
What does Article 21 actually require for supplier and supply chain security?
Article 21(2)(d) makes supply chain security a mandatory risk-management measure covering relationships with direct suppliers and service providers. Article 21(3) then requires that, when choosing these measures, you consider the vulnerabilities specific to each direct supplier, the overall quality of its products and cybersecurity practices — including secure-development procedures — and the results of EU coordinated critical supply chain risk assessments. In practice this means individualised assessment of each material supplier and documented, reasoned decisions.
How should a municipality tier its suppliers and focus due diligence?
Assess each supplier along several axes: the criticality of the service it supports, the level of access it holds to your systems and data, the sensitivity of processed information, incident history, reliance on subcontractors and exposure to third-country influence. Treat high-risk suppliers with deep diligence — audits, evidence of practices, closer review cycles — and lower-risk ones with a lighter questionnaire and periodic reassessment. Record tiering and findings in the supply-chain risk register with a named owner.
What should go into NIS2 supply-chain contract clauses?
At minimum: the supplier's duty to maintain agreed security measures; incident-notification timelines that align with your own NIS2 reporting obligations; a right to audit and inspect; business-continuity and recovery commitments; and an exit plan covering data return and migration on termination. In public procurement, express these as technical specifications and selection or award criteria in the tender documents up front so they survive evaluation and become enforceable contract terms.
How can the EU ICT Supply Chain Security Toolbox help a city operator?
Adopted by the NIS Cooperation Group (Member States, the Commission and ENISA), the toolbox gives a common EU approach to identifying, assessing and mitigating ICT supply chain risks. It outlines risk scenarios and mitigation measures, including assessing critical suppliers, using multi-vendor strategies and reducing dependence on high-risk suppliers, including third-country influence. A municipality can use it as a reference for its own vendor policy and as leverage in negotiations, but it does not replace national law.
Do supplier-security duties differ between essential and important entities?
The Article 21 supplier measures are broadly the same for both categories. The main difference is supervision and enforcement: essential entities generally face proactive (ex ante) supervision, with checks and evidence requests that can occur without an incident, while important entities are typically supervised reactively (ex post). Fines are also higher for essential entities. Both categories should keep documented supplier assessments, but essential entities should expect them to be examined more actively.
Sources and further reading
Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.
- Directive (EU) 2022/2555 (NIS2) — EUR-LexEUR-Lex, Publications Office of the European Union
- NIS2 Directive: securing network and information systemsEuropean Commission — Digital Strategy
- EU launches new toolbox to strengthen ICT supply chain securityEuropean Commission — Digital Strategy
- Toolbox to improve ICT supply chain securityEuropean Commission — Digital Strategy
- NIS2 Technical Implementation GuidanceENISA (European Union Agency for Cybersecurity)
- NIS2 — What are the requirements?Danish Agency for Digital Government (Digitaliseringsstyrelsen)